Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer

About GeoComply


We’re GeoComply! We are at the forefront of geolocation, cybersecurity, and anti-fraud innovation, developing and delivering cutting-edge technologies to help ensure regulatory compliance, combat bad online actors, alleviate user friction, and protect businesses from fraud.


Achieving significant business and revenue growth over the past three years and dubbed a tech “Unicorn,” GeoComply has been trusted by leading global brands and regulators for over ten years. Our compliance-grade geolocation technology solutions are installed on over 400 million devices and analyze over 12 billion transactions a year.


At the heart of it all is the people, united by a deep commitment to problem-solving and revolutionizing how people and businesses use the internet to instill confidence in every online interaction. With teams across five countries, three continents, and a global customer base, we have no plans to slow down.


As an Application Security Engineer at GeoComply, you’ll play a vital role in ensuring our applications are secure, resilient, and trustworthy. You’ll work within a team that influences secure design, performs code analysis, and identifies vulnerabilities through hands-on testing. This role involves designing, implementing, and maintaining robust security measures throughout the Software Development Lifecycle (SDLC), fostering a culture of security across development and operations teams.


Key Responsibilities
  • Application Security Review: Drive the secure development lifecycle by conducting design reviews, automated testing, and hands-on penetration testing to identify potential security vulnerabilities across applications and non-compliance with security standards.
  • Threat Modeling: Identify potential attack vectors and devise strategies to mitigate these threats.
  • Secure Design Consultation: Collaborate with development teams early in the SDLC to establish and integrate security requirements, ensuring robust security architecture for new projects and releases.
  • Security Tools Management: Implement and manage advanced security tools, focusing on automation. Leverage Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), security scanners, and bug bounty programs to assess and secure applications.
  • Developer Education & Engagement: Act as a security advocate within GeoComply’s development community. Educate software engineers on secure coding practices through training sessions, security guidelines, and one-on-one mentorship, fostering a strong security culture across teams.
  • Assisting During Incident Response: Serves as a trusted subject matter expert to bring application security expertise to root-cause analysis and remediation planning where appropriate.


Technical Proficiency
  • Proficient in at least one programming language relevant to GeoComply’s technology stack (e.g., Java, Golang, Python, JavaScript )
  • Experienced in deploying and configuring enterprise-grade security tools, including SAST, DAST, and security scanners.
  • Familiarity with leading security tools, such as BurpSuite, ZAP and Metasploit, for identifying and managing vulnerabilities.
  • Bug Bounty and Vulnerability Management: Skilled in supporting bug bounty programs, including triage, validation, and re-testing of security findings to ensure effective remediation.
  • Data Protection and Cryptography: Competence in designing secure solutions for sensitive data, applying cryptographic techniques, access controls, and hardware security modules (HSM) to protect critical assets.
  • Version Control Systems: Proficiency with Git (GitHub).
  • CI/CD and Automation Experience: Experienced in integrating security within CI/CD pipelines, utilizing tools like Jenkins, Artifactory, and related automation technologies.
  • Authorization & Networking Protocols: Familiarity with authentication/authorization frameworks (OAuth, SAML, OpenID, ADFS, SCIM) and a solid understanding of network and web related protocols (e.g. TCP/IP, UDP, HTTP, REST, DNS, SMTP).
  • Architecture Knowledge: In-depth understanding of web application architectures, APIs, microservices, and cloud-native systems.


Experience
  • Educational Background: Bachelor’s degree in Computer Science, Engineering, MIS, CIS, or a related discipline is required.
  • Professional Experience: 3+ years of experience in application security, including hands-on roles in code analysis, vulnerability identification, and secure design.


At GeoComply, we’re at the forefront of geolocation, cybersecurity, and anti-fraud innovation. Joining our team means working on cutting-edge technology with a group of passionate, skilled individuals who prioritize security, teamwork, and continuous growth. We offer a collaborative hybrid work environment and value in-person interaction while providing flexibility for our team members.


Apply Now!


Interested in joining our team? Send us your resume and a cover letter. We can’t wait to meet you!


Commitment to Diversity and Equity.

If you don't tick every box in this job description, please don't rule yourself out. Research suggests that women and other people in underrepresented groups tend to only apply if they meet every requirement. We focus on hiring people who value inclusion, collaboration, adaptability, courage, and integrity rather than ticking boxes, so if this resonates with you, please apply.


Search Firm Representatives Please Read Carefully

We do not accept unsolicited assistance from search firms for employment opportunities. All CVs or resumes submitted by search firms to any employee at our company without a valid written agreement in place for this position will be considered the sole property of our company. No fee will be paid if a candidate is hired by GeoComply due to an agency referral where no existing agreement exists with the GeoComply Talent Acquisition Team. Where agency agreements are in place, introductions must be through engagement by the GeoComply Talent Acquisition Team.



Why GeoComply?


Joining the GeoComply team means you’ll be part of an award-winning company to work, learn and grow. We are fast-paced, high-impact, and have a can-do team culture.


To be successful in our organization, you need an eager attitude, professionalism, and the confidence to willingly work to prove yourself and your ideas, and earn the trust of the organization.


Here’s why we think you’d love working with us.


We’re working towards something big

We’ve built a reputation as the global market leader for geolocation compliance solutions for over 10 years. We’re trusted by customers from all over the world, and the next few years will be particularly exciting as we continue to scale across new markets.


Our values aren’t just a buzzword

Our values are the foundation for what we as a company care about most. They signify the commitment we make to each other around how we act and what we stand for. They are our north star as we work together to build a company we’re all proud to be a part of. Learn more, here.


Diversity, equity, and inclusion are at the core of who we are

In collaboration with our team and external partners, we promote DEI in our recruitment and hiring practices; scholarships and financial aid; training and mentorship programs; employee benefits, and more.


Learning is at the heart of our employee experience

At GeoComply, we foster an environment that empowers every employee to gain the knowledge and abilities needed to perform at their very best and help our organization grow. From a professional development budget to local training opportunities, knowledge-sharing sessions and more, we are continually investing in employee career growth and development.


We believe in being a force for good

We profoundly care about our impact on the world and strive to make meaningful contributions to the communities we work and live in. Our Impact division focuses on philanthropic and social responsibility initiatives, including supporting our local communities, advancing equality, and harnessing our technology to protect vulnerable groups. Learn more, here.


We care about our team

Our GeoComply team is talented, driven and hard-working, and is known for its positive attitude and energy.  At GeoComply, we take care of our employees with the total package. Team members are generously rewarded with competitive salaries, incentives, and a comprehensive benefits program.


We value in-person collaboration

GeoComply culture thrives on a dynamic mix of in-person energy and independent focus and we champion a hybrid work model that blends the energy of in-person collaboration with the flexibility to work from home. Our 3-day in-office policy fosters teamwork and innovation, while also recognizing the importance of individual work styles and needs.


- - - - - - - - - -


At GeoComply, we live our value of Act with Integrity. Our workplace is built on mutual respect and inclusion, and we welcome applicants of all backgrounds, experiences, beliefs, and identities. Creating an accessible interview experience for all candidates is important to us. If you have any requests (big or small) throughout our hiring process, please don’t hesitate to let us know so we can do our best to prioritize your needs.


We care about your privacy and want you to be informed about your rights. Please read our Applicant Privacy Notice before applying for the position.

GeoComply Glassdoor Company Review
3.2 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
GeoComply DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of GeoComply
GeoComply CEO photo
Anna Sainsbury
Approve of CEO

Average salary estimate

$75000 / YEARLY (est.)
min
max
$60000K
$90000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer, GeoComply

Join the innovation leader in cybersecurity and geolocation as an Application Security Engineer at GeoComply in Warsaw, Poland! Here at GeoComply, we're dedicated to developing state-of-the-art technologies that secure online interactions and combat fraud. As an Application Security Engineer, you'll dive deep into enhancing the security of our applications throughout the Software Development Lifecycle (SDLC). With hands-on roles that include conducting code analysis and identifying vulnerabilities, you’ll work closely with our talented development teams. Your expertise will drive secure design reviews and automated testing, ensuring that our solutions stay ahead of potential threats. Collaborating with various departments, you’ll not only implement advanced security measures using tools like SAST and DAST but also educate your engineering colleagues on best practices for secure coding. Every day, you’ll help foster a strong security culture, creating an environment where security is everyone's priority. With your programming skills (Java, Golang, Python, or JavaScript) and experience in managing security tools, you’ll make a significant impact on our development projects. If you’re passionate about making the internet a safer place and want to be part of an exciting journey with a fast-growing 'Unicorn' company, this is the perfect opportunity for you! Come join our collaborative team that values inclusivity, continuous learning, and employee development, and help us protect businesses and users across the globe.

Frequently Asked Questions (FAQs) for Application Security Engineer Role at GeoComply
What does an Application Security Engineer do at GeoComply?

At GeoComply, an Application Security Engineer plays a crucial role in securing software applications throughout the development process. This includes conducting security reviews, vulnerability assessments, and implementing best practices to ensure applications are safe and reliable.

Join Rise to see the full answer
How can I prepare for the Application Security Engineer interview at GeoComply?

To prepare for an Application Security Engineer interview at GeoComply, familiarize yourself with secure coding practices, common security vulnerabilities, and the tools mentioned in the job description. Review your experiences with security assessments and be ready to discuss your approach to threat modeling.

Join Rise to see the full answer
What programming languages are preferred for the Application Security Engineer role at GeoComply?

GeoComply seeks candidates who are proficient in programming languages such as Java, Golang, Python, or JavaScript. Understanding these languages is essential for code analysis and implementing effective security measures.

Join Rise to see the full answer
What qualifications do I need to become an Application Security Engineer at GeoComply?

To apply for the Application Security Engineer position at GeoComply, a Bachelor’s degree in Computer Science, Engineering, or a related discipline is required, along with at least 3 years of professional experience in application security.

Join Rise to see the full answer
What tools should an Application Security Engineer be familiar with at GeoComply?

An Application Security Engineer at GeoComply should be experienced with security tools like SAST and DAST. Familiarity with BurpSuite, ZAP, and vulnerability management processes, such as bug bounty programs, is also beneficial.

Join Rise to see the full answer
What is the workplace culture like at GeoComply for an Application Security Engineer?

GeoComply promotes a collaborative and inclusive workplace culture, where the Application Security Engineer will thrive in a dynamic environment. Team members are encouraged to share ideas, continuously learn, and contribute to a strong security-focused culture within the organization.

Join Rise to see the full answer
How does GeoComply promote diversity in the Application Security Engineer role?

GeoComply is committed to diversity, equity, and inclusion, welcoming applicants from all backgrounds for the Application Security Engineer position. They believe in hiring based on skills and potential, ensuring that every voice is valued within the team.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer
Can you explain the Secure Development Lifecycle (SDLC) and its importance?

The SDLC is a structured process that ensures that security is integrated at every stage of software development. As an Application Security Engineer, you would highlight how it minimizes risks and promotes the development of resilient applications.

Join Rise to see the full answer
What is your experience with threat modeling?

Discuss your specific experience with threat modeling techniques. Explain how you identify potential threats and articulate strategies to mitigate those risks, tying it to real-world examples if possible.

Join Rise to see the full answer
Describe a time when you identified a vulnerability in an application.

Provide a specific example where you found a vulnerability. Discuss the analysis process, the tools used, and how you communicated your findings to the development team to ensure remediations.

Join Rise to see the full answer
What security tools have you used in previous roles?

List the security tools you are most familiar with, such as SAST, DAST, and their functionalities. Include any hands-on experience you've had with these tools and highlight successful outcomes.

Join Rise to see the full answer
How would you go about educating a development team on security practices?

Discuss your approach to training teams on security best practices, such as workshops, documentation, or mentorship programs. Highlight the importance of fostering a culture of security and collaboration.

Join Rise to see the full answer
What are some common vulnerabilities in web applications?

Mention well-known vulnerabilities like SQL injection, XSS, and CSRF. Discuss your past work experience addressing such vulnerabilities and how you've used security tools or practices to mitigate them.

Join Rise to see the full answer
How do you keep up with the latest trends in application security?

Describe your strategies for staying informed, such as following industry publications, attending conferences, or participating in online forums. Mention how this knowledge impacts your work as an Application Security Engineer.

Join Rise to see the full answer
What steps would you take during a security incident?

Outline your approach during incidents, from assessing the situation and conducting a root cause analysis to developing a remediation plan. Emphasize the importance of collaboration with various stakeholders.

Join Rise to see the full answer
Explain the importance of CI/CD pipelines in security.

Discuss how integrating security measures into CI/CD pipelines enables quicker identification and remediation of vulnerabilities, leading to safer deployments. Provide experiences related to this beneficial practice.

Join Rise to see the full answer
Can you give an example of how you’ve handled a bug bounty program?

Provide an example showcasing your involvement in a bug bounty program. Discuss your role in triaging submissions, validating findings, and working with developers on remediation strategies.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Posted 10 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Devsinc Remote No location specified
Posted 8 days ago
Photo of the Rise User
Posted 3 hours ago
Photo of the Rise User
Posted 7 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
November 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!